🌍

International Data Transfers

JP Sheet is operated by List Networks Ltd, registered in the United Kingdom, and serves buyers worldwide. Our servers are in Manchester and our team works remotely — we keep no customer data in any office. To deliver our service, your personal data is processed in several countries β€” under specific legal safeguards. Here's exactly where, why, and how it's protected.

Last updated: 19 September 2026

Where is your personal data processed?

Your personal data may be transferred to and processed in any of the following five regions, each for a specific purpose:

🇬🇧

United Kingdom

Company and servers

JP Sheet is operated by List Networks Ltd, a company registered in the United Kingdom. Our application servers are in Manchester. Your account, your orders and your reports are stored here, under UK data protection law. We work remotely and hold no customer data in any office.

πŸ‡―πŸ‡΅

Japan

Auction record retrieval

Our partner networks that retrieve original auction records sit on Japanese infrastructure. When you submit a chassis number, the lookup query is sent to Japan-based databases. Only the chassis number itself is transmitted β€” no buyer identity, no payment information.

🇺🇸

United States — vehicle records

VIN record retrieval

When you order a US or Canada VIN check, the vehicle identification number only is sent to the record providers — NMVTIS (the federal vehicle title database), salvage auction houses and dealer listing networks. No personal data goes with it. They receive a VIN and return records about that vehicle; they are never told who asked.

πŸ‡ΊπŸ‡Έ

United States

Analytics & marketing platforms

Hosted analytics (Google Analytics β€” IP-anonymised) and marketing platforms (Meta/Facebook Pixel, Google Ads, TikTok Pixel β€” only with your cookie consent). Page-view and event data may be transferred to US-based servers operated by these providers.

πŸ‡ͺπŸ‡Ί

European Union

Payment processing

Some payment processing is routed through Stripe and PayPal infrastructure that may include EU-based servers (depending on your billing country). Card data is handled entirely by these providers β€” JP Sheet never sees or stores it.

🌐

Global CDN edge

Cloudflare cache

Static assets (CSS, images, fonts, public pages) are served via Cloudflare's global CDN, which has edge servers in 300+ cities. Cached content is non-personal. No authenticated or payment pages are cached on the edge.

Which vendor processes what data?

A complete vendor-by-vendor breakdown for transparency:

Vendor What they process Region
Stripe Card numbers, expiry, CVV, billing email, amounts US / EU (depends on your country)
PayPal PayPal account email, transaction amounts US / EU / Luxembourg
Google Analytics Anonymised IP, page views, events (consent only) US
Meta / Facebook Pixel Conversion events, hashed identifiers (consent only) US / Ireland
Google Ads Conversion events, ad click identifiers (consent only); hashed email/phone for audience matching (Customer Match) US
TikTok Pixel Conversion events (consent only) US / EU / Singapore
Cloudflare IP addresses, request metadata (for security & CDN) Global edge network
Gemini (Google AI) Chassis number text only (for chassis decoder lookups) US
Japanese auction partners Chassis number only Japan
Hostinger (hosting) Application data, database United Kingdom

What safeguards protect your data when it crosses borders?

For data transfers out of the EU, UK and other regulated regions, we rely on the following safeguards:

πŸ“œ Standard Contractual Clauses (SCCs)

SCCs are EU-approved contracts that legally bind any vendor to GDPR-level data protection β€” no matter where they process data. Stripe, PayPal, Google, Meta, TikTok and Cloudflare all maintain SCCs with their EU customers, which means our use of them inherits these protections.

πŸ›‘οΈ Adequacy decisions

Some non-EU countries have received "adequacy decisions" from the European Commission, meaning the EU has formally confirmed that their data protection laws meet GDPR-equivalent standards. Where your data is transferred to one of these countries, no further safeguard is required.

Countries with current adequacy decisions: UK, Switzerland, Japan, South Korea, Canada (commercial), New Zealand, Israel, Argentina, Uruguay, Andorra, Faroe Islands, Guernsey, Isle of Man, Jersey, US (under the EU-US Data Privacy Framework).

πŸ” Encryption everywhere

All data transfers between regions happen over TLS 1.3 (the latest standard). At rest, sensitive data is encrypted using industry-standard algorithms (AES-256 or better). This protects your data even if a vendor's transmission line is intercepted.

πŸ“‹ Vendor due diligence

We only use vendors that publish their privacy and security commitments publicly, undergo independent audits (SOC 2, ISO 27001, PCI DSS where applicable), and provide GDPR-compliant data processing agreements.

Can I request a copy of these safeguards?

Yes. Under GDPR Article 46, you have the right to request a copy of the appropriate safeguards (such as the SCCs) used to transfer your data outside the EU/UK.

To request a copy, email [email protected] with the subject line "Data Transfer Safeguards Request". We will provide the relevant documentation (or a link to the publicly available version) within 30 days.

What are your rights regarding international transfers?

If you live in the EU, UK, or another GDPR-equivalent jurisdiction, you have specific rights when your data is transferred internationally:

For a full list of your data rights, see our Data Rights page.

πŸ“© Questions about where your data is processed?

Email us β€” we'll answer specifically about your data, the vendors involved, and the safeguards.

Email [email protected]

Related: Privacy Policy Β· Your Data Rights Β· California Privacy Β· Children's Privacy